Service protections
- HTTPS for the public production service and secure session settings.
- Authentication and server-side authorization based on accounts, workspaces, inboxes, and user roles.
- Logical separation of workspace data and controls that keep server credentials out of browser responses.
- Webhook signature or verification-token checks where required by the supported provider integration.
- Operational health checks, backups, queue monitoring, and controlled rollback procedures.
Secure channel connections
OAuth permissions and provider tokens are used only to operate the channels selected by an authorized administrator. Provider approval and access levels remain outside Ranan’s direct control.
Shared responsibility
- Customers must protect user accounts and devices, require appropriate access, review memberships, and secure connected-provider accounts.
- Administrators should remove obsolete access promptly and report suspected compromise through the verified support channel.
Payment information
The public Ranan website currently does not collect payment-card details. No PCI DSS, SOC 2, ISO 27001, or similar certification is claimed on this page.
Responsible reporting
Report potential vulnerabilities privately with reproduction steps and likely impact. Do not access data that is not yours, use social engineering, or impair service availability. Authorization for security testing must be obtained in writing.
No absolute guarantee
Security measures reduce risk but cannot eliminate it. Claims about encryption, certification, audit results, or response times are made only when supported by current evidence and an applicable agreement.
Questions and requests
Contact the Ranan operator
Use the verified channel associated with your workspace or service agreement. Never send passwords, access tokens, webhook secrets, or full payment-card details.
- Service operator
- Ranan
- Verified request channel
- Sign in to use your account contact channel